[Unbound-users] DNSSec validation
Nikos Mavrogiannopoulos
n.mavrogiannopoulos at gmail.com
Wed Oct 3 09:19:52 UTC 2012
On Wed, Oct 3, 2012 at 10:58 AM, W.C.A. Wijngaards <wouter at nlnetlabs.nl> wrote:
> The trust anchor was working all along, just fine.
> The server at 10.0.2.3, is your DNS resolver, and it does not have
> DNSSEC enabled. Use unbound without it: comment out the
> ub_ctx_resolvconf call. Unbound then goes into full resolver mode.
> It is wasteful and you have no fast cache hits, but it'll work with
> DNSSEC.
Now it is perfectly ok, thank you!
> It would be better (especially for bigger sites or bigger usage) to
> upgrade the upstream cache.
I'll notify the administrators here.
regards,
Nikos
More information about the Unbound-users
mailing list